National Vulnerability Database

National Vulnerability Database

CVE-2018-8024 Detail

Current Description

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.

Analysis Description

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because
they may have information that would be of interest to you. No inferences should be drawn on account of other sites
being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose.
NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further,
NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about
this page to nvd@nist.gov.

Change History

Modified Analysis -
2/28/2019 5:03:37 PM

Action

Type

Old Value

New Value

Changed

CPE Configuration

OR
*cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:* versions up to (including) 2.1.2
*cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:* versions from (including) 2.2.0 up to (including) 2.2.1
*cpe:2.3:a:apache:spark:2.3.0:*:*:*:*:*:*:*

OR
*cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:* versions from (including) 2.1.0 up to (including) 2.1.2
*cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:* versions from (including) 2.2.0 up to (including) 2.2.1
*cpe:2.3:a:apache:spark:2.3.0:*:*:*:*:*:*:*

Changed

CVSS V2

(AV:N/AC:M/Au:S/C:N/I:P/A:N)

(AV:N/AC:M/Au:S/C:P/I:P/A:N)

CVE Modified by MITRE -
2/20/2019 3:29:02 PM

Action

Type

Old Value

New Value

Changed

Description

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.

Initial Analysis -
9/10/2018 12:40:15 PM

Action

Type

Old Value

New Value

Added

CPE Configuration

OR
*cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:* versions up to (including) 2.1.2
*cpe:2.3:a:apache:spark:*:*:*:*:*:*:*:* versions from (including) 2.2.0 up to (including) 2.2.1
*cpe:2.3:a:apache:spark:2.3.0:*:*:*:*:*:*:*

CVE Modified by MITRE -
9/6/2018 10:29:01 AM

Action

Type

Old Value

New Value

Changed

Description

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, itâ??s possible for a malicious user to construct a URL pointing to a Spark clusterâ??s UIâ??s job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the userâ??s view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.

CVE Modified by MITRE -
9/5/2018 4:29:00 PM

Action

Type

Old Value

New Value

Changed

Description

In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI.

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, itâ??s possible for a malicious user to construct a URL pointing to a Spark clusterâ??s UIâ??s job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the userâ??s view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.